Mailing List archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[linux-dvb] Fw: [Bug 3344] I get this about once a day: "kernel: slab error in cache_free_debugcheck(): cache `size-32': double free, or memory outside object was overwritten" and system crashes.



 Hi andrew + dvb list,

stv0299 is a dvb frontend, so this is one for the dvb guys ;)

  Gerd

----- Forwarded message from Andrew Morton <akpm@osdl.org> -----

Date: Sun, 19 Sep 2004 11:56:24 -0700
From: Andrew Morton <akpm@osdl.org>
Subject: Fw: Re: Fw: [Bug 3344] I get this about once a day: "kernel: slab
 error in cache_free_debugcheck(): cache `size-32': double free, or memory
 outside object was overwritten" and system crashes.
To: Gerd Knorr <kraxel@bytesex.org>
Content-Type: text/plain; charset=ISO-8859-1
X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=0.16.4


He's right ;)

Begin forwarded message:

Date: Sun, 19 Sep 2004 20:35:02 +0200 (MEST)
From: Geert Uytterhoeven <geert@linux-m68k.org>
To: Andrew Morton <akpm@osdl.org>
Subject: Re: Fw: [Bug 3344] I get this about once a day: "kernel: slab error in cache_free_debugcheck(): cache `size-32': double free, or memory outside object was overwritten" and system crashes.


On Sun, 19 Sep 2004, Andrew Morton wrote:
> Begin forwarded message:
>
> Date: Sun, 19 Sep 2004 10:49:16 -0700
> From: bugme-daemon@osdl.org
> To: akpm@digeo.com
> Subject: [Bug 3344] I get this about once a day: "kernel: slab error in cache_free_debugcheck(): cache `size-32': double free, or memory outside object was overwritten" and system crashes.

Perhaps you wanted to send this message to Gerd Knorr?

>
>
> http://bugme.osdl.org/show_bug.cgi?id=3344
>
>
>
>
>
> ------- Additional Comments From loescher@gmx.de  2004-09-19 10:49 -------
> I have tried it with kerneö 2.6.9-rc2.
> Here is the result when running "modprobe -r stv0299":
>
> Sep 19 19:35:27 server kernel: slab error in cache_free_debugcheck(): cache
> `size-32': double free, or memory outside object was overwritten
> Sep 19 19:35:27 server kernel:  [truncate_complete_page+114/128]
> cache_free_debugcheck+0x162/0x270
> Sep 19 19:35:27 server kernel:  [<c013a1b2>] cache_free_debugcheck+0x162/0x270
> Sep 19 19:35:27 server kernel:  [shrink_list+601/1296] kfree+0x59/0xa0
> Sep 19 19:35:27 server kernel:  [<c013aee9>] kfree+0x59/0xa0
> Sep 19 19:35:27 server kernel:  [__crc_pci_get_slot+1461613/4835711]
> uni0299_detach+0x14/0x30 [stv0299]
> Sep 19 19:35:27 server kernel:  [<d1ce3094>] uni0299_detach+0x14/0x30 [stv0299]
> Sep 19 19:35:27 server kernel:  [__crc_pci_get_slot+1461613/4835711]
> uni0299_detach+0x14/0x30 [stv0299]
> Sep 19 19:35:27 server kernel:  [<d1ce3094>] uni0299_detach+0x14/0x30 [stv0299]
> Sep 19 19:35:27 server kernel:  [__crc_pci_get_slot+1526578/4835711] detach_devi
> ce+0x19/0x60 [dvb_core]
> Sep 19 19:35:27 server kernel:  [<d1cf2e59>] detach_device+0x19/0x60 [dvb_core]
> Sep 19 19:35:27 server kernel:  [__crc_pci_get_slot+1526732/4835711]
> unregister_i2c_client_from_bus+0x53/0x70 [dvb_core]
> Sep 19 19:35:27 server kernel:  [<d1cf2ef3>]
> unregister_i2c_client_from_bus+0x53/0x70 [dvb_core]
> Sep 19 19:35:27 server kernel:  [__crc_pci_get_slot+1526796/4835711]
> unregister_i2c_client_from_all_busses+0x23/0x40 [dvb_core]
> Sep 19 19:35:27 server kernel:  [<d1cf2f33>]
> unregister_i2c_client_from_all_busses+0x23/0x40 [dvb_core]
> Sep 19 19:35:27 server kernel:  [__crc_pci_get_slot+1527746/4835711]
> dvb_unregister_i2c_device+0x79/0x93 [dvb_core]
> Sep 19 19:35:27 server kernel:  [<d1cf32e9>] dvb_unregister_i2c_device+0x79/0x93
> [dvb_core]
> Sep 19 19:35:27 server kernel:  [__crc_pci_get_slot+1461656/4835711]
> exit_uni0299+0xf/0x13 [stv0299]
> Sep 19 19:35:27 server kernel:  [<d1ce30bf>] exit_uni0299+0xf/0x13 [stv0299]
> Sep 19 19:35:27 server kernel:  [__crc_pci_get_slot+1461385/4835711]
> uni0299_attach+0x0/0xd0 [stv0299]
> Sep 19 19:35:27 server kernel:  [<d1ce2fb0>] uni0299_attach+0x0/0xd0 [stv0299]
> Sep 19 19:35:27 server kernel:  [load_module+2127/2800]
> sys_delete_module+0x19f/0x1b0
> Sep 19 19:35:27 server kernel:  [<c012c64f>] sys_delete_module+0x19f/0x1b0
> Sep 19 19:35:27 server kernel:  [try_to_unmap_cluster+436/448] do_munmap+0x154/0
> 0x1b0
> Sep 19 19:35:27 server kernel:  [<c0144324>] do_munmap+0x154/0x1b0
> Sep 19 19:35:27 server kernel:  [irq_entries_start+123/128] syscall_call+0x7/0xb
> Sep 19 19:35:27 server kernel:  [<c01042bb>] syscall_call+0x7/0xb
> Sep 19 19:35:27 server kernel: ccab9b44: redzone 1: 0x5a2cf071, redzone 2:
> 0x5a2cf071.
> Sep 19 19:35:38 server sshd[3639]: Accepted password for root from 10.3.3.1 port
> 1023
> Sep 19 19:35:59 server kernel: slab: double free detected in cache 'size-32',
> objp ccab9b44.
> Sep 19 19:35:59 server kernel: ------------[ cut here ]------------
> Sep 19 19:35:59 server kernel: kernel BUG at mm/slab.c:2139!
> Sep 19 19:35:59 server kernel: invalid operand: 0000 [#1]
> Sep 19 19:35:59 server kernel: PREEMPT
> Sep 19 19:35:59 server kernel: Modules linked in: dvb_ttpci dvb_core saa7146_vv
> video_buf saa7146 v4l1_compat v4l2_common videodev ttpci_eeprom firmware_class
> Sep 19 19:35:59 server kernel: CPU:    0
> Sep 19 19:35:59 server kernel: EIP:    0060:[remove_shrinker+5/96]    Not
> tainted VLI
> Sep 19 19:35:59 server kernel: EIP:    0060:[<c013a8a5>]    Not tainted VLI
> Sep 19 19:35:59 server kernel: EFLAGS: 00010082   (2.6.8.1)
> Sep 19 19:35:59 server kernel: EIP is at free_block+0xe5/0x150
> Sep 19 19:35:59 server kernel: eax: 00000041   ebx: ccab9000   ecx: c031ea4c
> edx: c031ea4c
> Sep 19 19:35:59 server kernel: esi: 0000003d   edi: ccab9b44   ebp: cffef040
> esp: cffb1ecc
> Sep 19 19:35:59 server kernel: ds: 007b   es: 007b   ss: 0068
> Sep 19 19:35:59 server kernel: Process events/0 (pid: 3, threadinfo=cffb0000
> task=cffdc020)
> Sep 19 19:35:59 server kernel: Stack: c02e4580 c02e376b ccab9b44 cffef04c
> cffef05c ccab9018 00000003 c12710b4
> Sep 19 19:35:59 server kernel:        c12710a4 00000007 cffef040 c013b23a
> cffef040 c12710b4 00000007 cffef71c
> Sep 19 19:35:59 server kernel:        cffef040 cffb0000 00000001 c013b309
> cffef040 c12710a4 00000000 cffef71c
> Sep 19 19:35:59 server kernel: Call Trace:
> Sep 19 19:35:59 server kernel:  [shrink_cache+154/864] drain_array_locked+0x8a/0xd0
> Sep 19 19:35:59 server kernel:  [<c013b23a>] drain_array_locked+0x8a/0xd0
> Sep 19 19:35:59 server kernel:  [shrink_cache+361/864] cache_reap+0x89/0x200
> Sep 19 19:35:59 server kernel:  [<c013b309>] cache_reap+0x89/0x200
> Sep 19 19:35:59 server kernel:  [param_get_int+32/48] worker_thread+0x1d0/0x2b0
> Sep 19 19:35:59 server kernel:  [<c01261b0>] worker_thread+0x1d0/0x2b0
> Sep 19 19:35:59 server kernel:  [shrink_cache+224/864] cache_reap+0x0/0x200
> Sep 19 19:35:59 server kernel:  [<c013b280>] cache_reap+0x0/0x200
> Sep 19 19:35:59 server kernel:  [sys_sched_setaffinity+48/256]
> default_wake_function+0x0/0x20
> Sep 19 19:35:59 server kernel:  [<c0112b20>] default_wake_function+0x0/0x20
> Sep 19 19:35:59 server kernel:  [sys_sched_setaffinity+48/256]
> default_wake_function+0x0/0x20
> Sep 19 19:35:59 server kernel:  [<c0112b20>] default_wake_function+0x0/0x20
> Sep 19 19:35:59 server kernel:  [parse_args+208/272] worker_thread+0x0/0x2b0
> Sep 19 19:35:59 server kernel:  [<c0125fe0>] worker_thread+0x0/0x2b0
> Sep 19 19:35:59 server kernel:  [use_module+104/304] kthread+0xa8/0xe0
> Sep 19 19:35:59 server kernel:  [<c012a408>] kthread+0xa8/0xe0
> Sep 19 19:35:59 server kernel:  [already_uses+0/64] kthread+0x0/0xe0
> Sep 19 19:35:59 server kernel:  [<c012a360>] kthread+0x0/0xe0
> Sep 19 19:35:59 server kernel:  [kernel_thread+85/144] kernel_thread_helper+0x5/0x10
> Sep 19 19:35:59 server kernel:  [<c01022c5>] kernel_thread_helper+0x5/0x10
> Sep 19 19:35:59 server kernel: Code: c6 e8 40 fa ff ff 8d 53 18 89 54 24 14 66
> 83 3c 72 fe 74 1f 89 7c 24 08 8b 45 6c c7 04 24 80 45 2e c0 89 44 24 04 e8 bb bd
> fd ff <0f> 0b 5b 08 61 37 2e c0 0f b7 43 14 8b 54 24 14 66 89 04 72 66
> Sep 19 19:35:59 server kernel:  <6>note: events/0[3] exited with preempt_count 1
>
>
> ------- You are receiving this mail because: -------
> You are the assignee for the bug, or are watching the assignee.
>

Gr{oetje,eeting}s,

						Geert

--
Geert Uytterhoeven -- Sony Network and Software Technology Center Europe (NSCE)
Geert.Uytterhoeven@sonycom.com ------- The Corporate Village, Da Vincilaan 7-D1
Voice +32-2-7008453 Fax +32-2-7008622 ---------------- B-1935 Zaventem, Belgium

----- End forwarded message -----

-- 
return -ENOSIG;




Home | Main Index | Thread Index